cryptocat project records
17 published records for vendor cryptocat project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-20 Improper Input Validation4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-331 Insufficient Entropy1
- CWE-326 Inadequate Encryption Strength1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2013-4103Proof of concept | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user inputcryptocat project · cryptocat · CWE-20 | Critical9.8 | — | 6.9% | Nov 4, 2019 |
40Plan | CVE-2013-2259No exploit | Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overviewcryptocat project · cryptocat · CWE-20 | Critical9.8 | — | 3.7% | Nov 4, 2019 |
40Plan | CVE-2013-2260No exploit | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weaknesscryptocat project · cryptocat · CWE-331 | Critical9.8 | — | 2.2% | Nov 4, 2019 |
39Monitor | CVE-2013-4108No exploit | Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.cryptocat project · cryptocat | Critical9.8 | — | 1.5% | Nov 14, 2019 |
37Monitor | CVE-2013-4102No exploit | Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weaknesscryptocat project · cryptocat · CWE-330 | Critical9.1 | — | 2.0% | Nov 4, 2019 |
33Monitor | CVE-2013-2261Proof of concept | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosurecryptocat project · cryptocat · CWE-200 | High7.5 | — | 11.6% | Nov 4, 2019 |
31Monitor | CVE-2013-4100No exploit | Cryptocat before 2.0.22 has Remote Denial of Service via usernamecryptocat project · cryptocat · CWE-20 | High7.5 | — | 2.4% | Nov 4, 2019 |
31Monitor | CVE-2013-2257No exploit | Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weaknesscryptocat project · cryptocat · CWE-307 | High7.5 | — | 2.0% | Nov 4, 2019 |
31Monitor | CVE-2013-2262No exploit | Cryptocat strophe.js before 2.0.22 has information disclosurecryptocat project · cryptocat · CWE-200 | High7.5 | — | 1.9% | Nov 4, 2019 |
30Monitor | CVE-2013-4105No exploit | Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosurecryptocat project · cryptocat · CWE-200 | High7.5 | — | 1.1% | Nov 4, 2019 |
30Monitor | CVE-2013-4104No exploit | Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocolcryptocat project · cryptocat · CWE-326 | High7.5 | — | 0.8% | Nov 4, 2019 |
25Monitor | CVE-2013-4109No exploit | An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.cryptocat project · cryptocat · CWE-79 | Medium6.1 | — | 1.7% | Nov 14, 2019 |
24Monitor | CVE-2013-4106No exploit | A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.cryptocat project · cryptocat · CWE-79 | Medium6.1 | — | 1.5% | Nov 14, 2019 |
24Monitor | CVE-2013-4107No exploit | Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scriptingcryptocat project · cryptocat · CWE-79 | Medium6.1 | — | 1.1% | Nov 5, 2019 |
22Monitor | CVE-2013-4110No exploit | Cryptocat has an Unspecified Chat Participant User List Disclosurecryptocat project · cryptocat · CWE-200 | Medium5.3 | — | 2.0% | Nov 5, 2019 |
21Monitor | CVE-2013-2258No exploit | Cryptocat before 2.0.22 has Nickname User Impersonationcryptocat project · cryptocat | Medium5.3 | — | 1.4% | Nov 4, 2019 |
21Monitor | CVE-2013-4101No exploit | Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weaknesscryptocat project · cryptocat · CWE-20 | Medium5.3 | — | 1.4% | Nov 4, 2019 |
- CVE-2013-410341Plan
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
CriticalCVSS 9.8Proof of conceptEPSS 7%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-225940Plan
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
CriticalCVSS 9.8No exploitEPSS 4%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-226040Plan
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
CriticalCVSS 9.8No exploitEPSS 2%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-410839Monitor
Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.
CriticalCVSS 9.8No exploitEPSS 2%cryptocat project · cryptocatNov 14, 2019
- CVE-2013-410237Monitor
Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
CriticalCVSS 9.1No exploitEPSS 2%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-226133Monitor
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
HighCVSS 7.5Proof of conceptEPSS 12%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-410031Monitor
Cryptocat before 2.0.22 has Remote Denial of Service via username
HighCVSS 7.5No exploitEPSS 2%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-225731Monitor
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
HighCVSS 7.5No exploitEPSS 2%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-226231Monitor
Cryptocat strophe.js before 2.0.22 has information disclosure
HighCVSS 7.5No exploitEPSS 2%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-410530Monitor
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
HighCVSS 7.5No exploitEPSS 1%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-410430Monitor
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
HighCVSS 7.5No exploitEPSS 1%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-410925Monitor
An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
MediumCVSS 6.1No exploitEPSS 2%cryptocat project · cryptocatNov 14, 2019
- CVE-2013-410624Monitor
A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
MediumCVSS 6.1No exploitEPSS 1%cryptocat project · cryptocatNov 14, 2019
- CVE-2013-410724Monitor
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
MediumCVSS 6.1No exploitEPSS 1%cryptocat project · cryptocatNov 5, 2019
- CVE-2013-411022Monitor
Cryptocat has an Unspecified Chat Participant User List Disclosure
MediumCVSS 5.3No exploitEPSS 2%cryptocat project · cryptocatNov 5, 2019
- CVE-2013-225821Monitor
Cryptocat before 2.0.22 has Nickname User Impersonation
MediumCVSS 5.3No exploitEPSS 1%cryptocat project · cryptocatNov 4, 2019
- CVE-2013-410121Monitor
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
MediumCVSS 5.3No exploitEPSS 1%cryptocat project · cryptocatNov 4, 2019